Courseiva

CND · topic practice

Endpoint Protection practice questions

Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) Endpoint Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Endpoint Protection

What the exam tests

What to know about Endpoint Protection

IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.

IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).

SLAAC vs DHCPv6 vs stateful assignment.

Neighbor Discovery Protocol replacing ARP.

IPv6 routing differences and dual-stack coexistence.

Watch out for

Common Endpoint Protection exam traps

  • Link-local addresses are not routable beyond the local link.
  • SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
  • NDP uses ICMPv6, not ARP.
  • An IPv6 prefix is /64 for most host subnets, not /24.

Practice set

Endpoint Protection questions

20 questions · select your answer, then reveal the explanation

An Incident Responder analyzing a compromised Linux server suspects a rootkit has modified system binaries. The responder runs the package manager verification command on Debian/Ubuntu to check installed packages against the package database. Which command is appropriate?

An organization's Endpoint Detection and Response (EDR) platform flags a suspicious PowerShell command line executing an encoded script block. Which Windows logging subsystem should the security analyst inspect for the decoded script contents?

A security engineer is configuring mobile device management (MDM) for corporate-owned iOS devices. To prevent users from installing unauthorized apps while still allowing access to enterprise applications, which feature should be deployed?

A security analyst is preparing to harden a fleet of corporate Windows 10 endpoints against pass-the-hash attacks. Which built-in Windows feature should be enabled and configured to isolate LSASS memory using virtualization?

An enterprise environment uses Microsoft Endpoint Configuration Manager (MECM) for patch management. An administrator needs to ensure that critical patches are installed on workstations with minimal user disruption outside of active hours. Which MECM feature should be configured?

An administrator needs to enforce mandatory password complexity, minimum length, and account lockout policies for local user accounts on standalone Windows Server endpoints that are not joined to an Active Directory domain. Which tool should be used?

An administrator is troubleshooting a Linux endpoint running Ubuntu where AppArmor is operating in enforcing mode, but a critical daemon keeps failing to write to its log file. Which command should the administrator run to temporarily switch the profile for this specific daemon to complain mode without affecting the rest of the system?

A security administrator needs to configure Windows Defender Firewall with Advanced Security via Group Policy Object (GPO) to block all outbound connections except those explicitly permitted by a rule. Where should the administrator configure this setting?

An IoT device deployed in an industrial environment runs a minimal Linux kernel and needs its attack surface reduced by disabling unnecessary kernel modules like USB storage and Bluetooth. Where should the administrator configure module blacklisting?

A security architect is configuring Linux Unified Key Setup (LUKS) disk encryption on enterprise laptops. To ensure that the encryption key can be decrypted automatically during boot via a Trusted Platform Module (TPM) 2.0 chip without manual passphrase entry, which tool should be integrated?

Question 11mediummultiple choice
Read the full wireless explanation →

A security administrator is evaluating Mobile Threat Defense (MTD) solutions for corporate Android devices. The administrator needs a solution that can detect rogue Wi-Fi access points and Man-in-the-Middle (MitM) attacks at the network layer. Which capability must the MTD solution provide?

An enterprise endpoint security policy requires that all USB mass storage devices be blocked on workstations, while allowing encrypted company-issued smart cards and input devices. Which configuration approach should an administrator take using Group Policy?

A system administrator is hardening a fleet of Linux servers by setting strict umask values for all users to ensure newly created files are not readable by others. Where should this default system-wide umask be configured?

An organization's security team is deploying an EDR agent across corporate endpoints. During testing, the agent's kernel-mode driver causes a Blue Screen of Death (BSOD) during boot on systems running a third-party disk encryption filter driver. Which administrative action should be taken first to isolate and remediate the driver conflict?

An Incident Response team is investigating a Linux server where a persistent backdoor is suspected of hiding process IDs (PIDs) using user-space hooks. Which utility should the responder use to compare process lists returned by the kernel system call table against direct kernel memory inspection?

A security analyst is reviewing vulnerability assessment reports for a fleet of Windows endpoints and notes that third-party software (such as browsers and PDF readers) accounts for most missing patches. Which deployment strategy should the organization implement to streamline third-party patch management?

An administrator wants to ensure that critical system files on Windows endpoints are automatically monitored for unauthorized modifications and that any changes trigger an alert. Which built-in Windows tool or feature should be utilized?

A security engineer is configuring Linux Auditd on enterprise servers to log all attempts to modify user and group databases. Which audit rule should be added to /etc/audit/audit.rules?

An organization is hardening Android enterprise devices and wants to prevent users from installing applications from unknown sources while ensuring corporate apps update automatically. Which policy configuration in the EMM/MDM console achieves this?

A security analyst is investigating an EDR alert where a process spawned a suspicious child process. The analyst needs to review the process lineage tree. Which EDR capability is most useful for this task?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Endpoint Protection sessions

Start a Endpoint Protection only practice session

Every question in these sessions is drawn from the Endpoint Protection domain — nothing else.

Related practice questions

Related CND topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CND exam test about Endpoint Protection?
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Endpoint Protection questions in a focused session?
Yes — the session launcher on this page draws every question from the Endpoint Protection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CND topics?
Use the topic links above to move to related areas, or go back to the CND question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CND exam covers. They are not copied from any real exam or dump site.